English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 28026
À§Çèµµ 30
Æ÷Æ® 139,445
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù SMB
»ó¼¼¼³¸í ÇØ´ç Microsoft SQL ¼­¹ö´Â ¼³Ä¡ ÆÐ½º¿öµå¸¦ ¾ÈÀüÇÏÁö ¾ÊÀº °÷¿¡ ÀúÀåÇϰí ÀÖ´Ù.
MS SQL ¼­¹öÀÇ ¼³Ä¡ °úÁ¤¿¡¼­ setup.iss ¼³Ä¡ ÆÄÀÏÀ̳ª sqlstp.log ÆÄÀϰú sqlspX.log ·Î±× ÆÄÀϵ鿡 ¾ÏȣȭµÇÁö ¾ÊÀº ä·Î, ȤÀº Çã¼úÇÑ ¾Ïȣȭ ¹æ½ÄÀ¸·Î ÀúÀåµÉ ¼ö ÀÖ´Â ¾î¶² ¼³Ä¡ ÆÐ½º¿öµåµéÀ» ³²°Ü ³õÀ» ¼ö ÀÖ´Ù. ÀÌ ÆÄÀϵéÀº µÎ ±ºµ¥¿¡ ±â·ÏµÈ´Ù. ù¹øÂ°´Â %WINNT% µð·ºÅ丮 (´ëºÎºÐÀÇ ½Ã½ºÅÛÀº C:\Winnt)¿¡ ÀÖ´Ù. µÎ¹øÂ° Àå¼Ò´Â %SQLSERVERINSTANCE%\install ÀÌ´Ù.
ÀÌ ÆÄÀϵéÀº ºÎÀûÀýÇÑ ÆÄÀÏ ¾×¼¼½º ±ÇÇÑÀ» °¡Áö°í »ý¼ºµÇ±â ¶§¹®¿¡ SQL ¼­¹ö°¡ ÀÛµ¿Çϰí ÀÖ´Â ½Ã½ºÅÛ»ó¿¡ ·Î±×¿Â ÇÒ ¼ö ÀÖ´Â ¿ø°ÝÁöÀÇ °ø°ÝÀÚ¶ó¸é ±× ÆÄÀϵéÀ» ¾×¼¼½ºÇÏ¿© ÆÐ½º¿öµåµéÀ» ã¾Æ³¾ ¼ö ÀÖ´Ù. À̰ÍÀº °ø°ÝÀÚ°¡ SQL ¼­¹ö¿¡ ´ëÇÑ °ü¸®ÀÚ ±ÇÇÑÀ» ¾òÀ» ¼ö ÀÖ°Ô ÇØ ÁØ´Ù.
¿¹¸¦µé¾î, setup.iss ÆÄÀÏÀ» ¿ÀÇÂÇÏ¸é ´ÙÀ½°ú °°Àº ÅØ½ºÆ®µéÀ» º¼ ¼ö ÀÖÀ» °ÍÀÌ´Ù:

[ServerConnect-0]
NTAuthentication=0
SQLAuthentication=1
svPassword=0536f618eca8

"svPassword="À¸·Î ½ÃÀÛÇÏ´Â ¶óÀÎÀº °£´ÜÇÏ°Ô ÇØµ¶ÇÒ ¼ö ÀÖ´Â ¾ÏÈ£¸¦ °¡Áö°í ÀÖ´Ù.

* Âü°í:
http://www.cert.org/advisories/CA-2002-22.html
http://www.kb.cert.org/vuls/id/338195
http://archives.neohapsis.com/archives/bugtraq/2002-07/0108.html
http://marc.theaimsgroup.com/?l=bugtraq&m=102640092826731&w=2
http://marc.theaimsgroup.com/?l=vuln-dev&m=102640394131103&w=2
http://www.appsecinc.com/resources/alerts/mssql/02-0009.html

* Âü°í »çÀÌÆ®:
http://www.securityfocus.com/bid/5203

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Microsoft MSDE 1.0
Microsoft SQL Server 2000
Microsoft SQL Server 7.0
Microsoft Windows Any version
ÇØ°áÃ¥ 1. ÀÌ Ãë¾àÁ¡¿¡ ÀÇÇØ ÆÐ½º¿öµåµéÀÌ ³ëÃâµÇ¾úÀ» ¼ö ÀÖÀ¸¹Ç·Î ÆÐ½º¿öµå¸¦ ¹Ù²ã¾ß ÇÑ´Ù. sa °èÁ¤¿¡ ´ëÇÑ ÆÐ½º¿öµå´Â SQL Query â¿¡¼­ ´ÙÀ½°ú °°Àº ¸í·ÉÀ» ÀÌ¿ëÇÏ¿© ¹Ù²Ü ¼ö ÀÖ´Ù.

exec sp_password NULL,'hard!2guess','sa'

2. ÆÐ½º¿öµåµéÀ» °¡Áö°í ÀÖ´Â ¸ðµç ÆÄÀϵéÀ» ã¾Æ¼­ »èÁ¦ÇÏ¿©¾ß ÇÑ´Ù. ¸¶ÀÌÅ©·Î¼ÒÇÁÆ®»ç´Â ¾×¼¼½º °¡´ÉÇÑ ¸ðµç µð·ºÅ丮·ÎºÎÅÍ ÆÐ½º¿öµåµéÀ» Á¦°ÅÇØ ÁÖ´Â killpwd.exe ¶ó´Â À¯Æ¿¸®Æ¼¸¦ Á¦°øÇϰí ÀÖ´Ù. ÀÌ ÆÄÀÏÀº ¾Æ·¡¿¡ ÀÖ´Â ¸¶ÀÌÅ©·Î¼ÒÇÁÆ® º¸¾È °Ô½Ã¹° MS02-035 ·ÎºÎÅÍ ´Ù¿î·Îµå °¡´ÉÇÏ¸ç ¼­¹ö»ó¿¡¼­ ¼öÇà½ÃŰ¸é µÈ´Ù:
http://www.microsoft.com/technet/security/bulletin/MS02-035.asp
°ü·Ã URL CVE-2002-0643 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)